HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 | Vendor Advisory |
Configurations
History
18 Mar 2026, 20:38
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hcltech aion
Hcltech |
|
| Summary |
|
|
| CPE | cpe:2.3:a:hcltech:aion:*:*:*:*:*:*:*:* | |
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 - Vendor Advisory |
16 Mar 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-345 |
16 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 15:16
Updated : 2026-03-18 20:38
NVD link : CVE-2025-52645
Mitre link : CVE-2025-52645
CVE.ORG link : CVE-2025-52645
JSON object : View
Products Affected
hcltech
- aion
CWE
CWE-345
Insufficient Verification of Data Authenticity
